Maven package intelligence
org.apache.activemq:activemq-broker Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting the Maven package org.apache.activemq:activemq-broker, including the gap beyond CISA KEV, confidence assessments, and sensor observations.
- Total KEVs
- 1
- Known exploited vulnerability affecting org.apache.activemq:activemq-broker
- In CISA KEV
- 1
- Records also listed in the official catalog
- Beyond CISA KEV
- 0
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 0
- org.apache.activemq:activemq-broker KEVs with sensor-observed exploitation activity
Review org.apache.activemq:activemq-broker exploitation against the versions you run
All one exploited org.apache.activemq:activemq-broker vulnerability tracked here is also listed in CISA KEV.
- 100%
- Covered by CISA
- 0%
- Beyond CISA
Attested org.apache.activemq:activemq-broker vulnerabilities
1 known exploited vulnerability affecting this package.
| Vulnerability | CISA KEV | Added |
|---|---|---|
|
CVE-2026-34197
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans |
In CISA | 01 Jun 2026 |
Recurring weakness patterns
Improper Input Validation, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), and Improper Control of Generation of Code ('Code Injection') account for mapped occurrences across this org.apache.activemq:activemq-broker KEV portfolio.